Seneste forumindlæg
Køb / Salg
 * Uofficiel Black/White liste V3
Login / opret bruger

Forum \ Software \ Sikkerhed
Denne tråd er over 6 måneder gammel

Er du sikker på, at du har noget relevant at tilføje?

HJT log igen igen igen igen igen

Af Semi Supporter rUb!n4z | 21-10-2004 15:00 | 819 visninger | 8 svar, hop til seneste
Hej! Vil ikke være SØDE at tjekke min HJT log? Logfile of HijackThis v1.97.7 Scan saved at 15:00:45, on 21-10-2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSSystem32Ati2evxx.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSExplorer.EXE C:WINDOWSsystem32spoolsv.exe C:ProgrammerLogitechiTouchiTouch.exe C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE C:ProgrammerMessenger Plus! 2MsgPlus.exe C:ProgrammerD-Toolsdaemon.exe C:ProgrammeriTunesiTunesHelper.exe C:ProgrammerQuickTimeqttask.exe C:WINDOWSSOUNDMAN.EXE C:ProgrammerJavaj2re1.4.2_05injusched.exe C:WINDOWSSystem32DRIVERSCDANTSRV.EXE C:ProgrammerGoogleGmail Notifiergnotify.exe C:WINDOWSSystem32svchost.exe C:Program FilesWinad ClientWinad.exe C:WINDOWSSystem32ctfmon.exe C:ProgrammerLogitechDesktop Messenger8876480ProgramBackWeb-8876480.exe C:ProgrammerMicrosoft ActiveSyncWCESCOMM.EXE C:ProgrammerSpybot - Search & DestroyTeaTimer.exe C:progra~1steamsteam.exe C:ProgrammerMSN Messengermsnmsgr.exe C:ProgrammereBayeBay Toolbar4.4.0.1ebaytbar.exe C:WINDOWSSystem32WinSvc32MsSvc32.exe C:ProgrammeriPodiniPodService.exe C:ProgrammerInternet Exploreriexplore.exe C:ProgrammerInternet ExplorerIEXPLORE.EXE C:ProgrammerInternet ExplorerIEXPLORE.EXE C:ProgrammerWeb_RebatesWebRebates1.exe C:Program FilesWinad ClientWinClt.exe C:WINDOWSSystem32wuauclt.exe C:ProgrammereMuleemule.exe C:ProgrammerWeb_RebatesWebRebates0.exe C:ProgrammerFælles filerRealUpdate_OB ealsched.exe C:ProgrammerInternet ExplorerIEXPLORE.EXE J:Ny mappeNy mappeNy mappeNy mappeNy mappeNy mappeNy mappeNy mappeHijackThis.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.dk[...] R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = localhost R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks F0 - system.ini: Shell= F2 - REG:system.ini: Shell= O2 - BHO: (no name) - {00000015-A527-34E7-25C2-03A4E313B2E9} - c:WINDOWSsystem32winsrvs_1.dll O2 - BHO: (no name) - {001F2570-5DF5-11d3-B991-00A0C9BB0874} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:programmergooglegoogletoolbar1.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:programmergooglegoogletoolbar1.dll O3 - Toolbar: eBay Toolbar - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O4 - HKLM..Run: [zBrowser Launcher] C:ProgrammerLogitechiTouchiTouch.exe O4 - HKLM..Run: [EM_EXEC] C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE O4 - HKLM..Run: [TkBellExe] "C:ProgrammerFælles filerRealUpdate_OB ealsched.exe" -osboot O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit O4 - HKLM..Run: [MessengerPlus2] "C:ProgrammerMessenger Plus! 2MsgPlus.exe" O4 - HKLM..Run: [DAEMON Tools-1033] "C:ProgrammerD-Toolsdaemon.exe" -lang 1033 O4 - HKLM..Run: [iTunesHelper] C:ProgrammeriTunesiTunesHelper.exe O4 - HKLM..Run: [QuickTime Task] "C:ProgrammerQuickTimeqttask.exe" -atboottime O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM..Run: [SunJavaUpdateSched] C:ProgrammerJavaj2re1.4.2_05injusched.exe O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe O4 - HKLM..Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:ProgrammerGoogleGmail Notifiergnotify.exe O4 - HKLM..Run: [Winad Client] C:Program FilesWinad ClientWinad.exe O4 - HKLM..Run: [WebRebates0] "C:ProgrammerWeb_RebatesWebRebates0.exe" O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe O4 - HKCU..Run: [LDM] C:ProgrammerLogitechDesktop Messenger8876480ProgramBackWeb-8876480.exe O4 - HKCU..Run: [H/PC Connection Agent] "C:ProgrammerMicrosoft ActiveSyncWCESCOMM.EXE" O4 - HKCU..Run: [SpybotSD TeaTimer] C:ProgrammerSpybot - Search & DestroyTeaTimer.exe O4 - HKCU..Run: [MessengerPlus2] "C:ProgrammerMessenger Plus! 2MsgPlus.exe" /WinStart O4 - HKCU..Run: [Steam] "c:progra~1steamsteam.exe" -silent O4 - HKCU..Run: [msnmsgr] "C:ProgrammerMSN Messengermsnmsgr.exe" /background O4 - HKLM..RunOnce: [djtopr1150.exe] "C:DOCUME~1ANDERS~1LOKALE~1Tempdjtopr1150.exe" O4 - HKLM..RunOnce: [SpybotSnD] "C:ProgrammerSpybot - Search & DestroySpybotSD.exe" /autocheck O4 - Startup: Anapod Manager.lnk = C:ProgrammerRed Chair SoftwareAnapod Exploreranamgr.exe O4 - Global Startup: eBay Toolbar.LNK = C:ProgrammereBayeBay Toolbar4.4.0.1ebaytbar.exe O4 - Global Startup: MsSvc32.exe O4 - Global User Startup: eBay Toolbar.LNK = C:ProgrammereBayeBay Toolbar4.4.0.1ebaytbar.exe O4 - Global User Startup: MsSvc32.exe O8 - Extra context menu item: &Google Search - res://c:programmergoogleGoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Download with GetRight - C:ProgrammerGetRightGRdownload.htm O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:PROGRA~1MICROS~3OFFICE11EXCEL.EXE/3000 O8 - Extra context menu item: Open with GetRight Browser - C:ProgrammerGetRightGRbrowse.htm O8 - Extra context menu item: Translate into English - res://c:programmergoogleGoogleToolbar1.dll/cmtrans.html O8 - Extra context menu item: Web Rebates - file://C:ProgrammerWeb_RebatesSy1150Tp1150scri1150a.htm O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra button: Opret Foretrukken på mobil enhed (HKLM) O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... (HKLM) O9 - Extra button: Opslag (HKLM) O9 - Extra button: eBay Toolbar (HKLM) O9 - Extra 'Tools' menuitem: eBay Toolbar (HKLM) O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} - O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com[...] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com[...] O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com[...] O17 - HKLMSystemCCSServicesTcpip..{8797E844-69B0-480B-9A91-EC892C437062}: NameServer = 192.168.2.1 O17 - HKLMSystemCCSServicesTcpip..{F54E0DEE-9163-42B0-B68D-8088A0D1C35A}: NameServer = 192.168.2.1 Tuuuusind tak! -Anders
--
"Life is so... Whatever!" Kelly Marquette aKa Skeletor
#1
Armageddon
Moderator
21-10-2004 15:44

Rapporter til Admin
Hejsa, Der er et par småting som lige skal fixes. Start med at deaktivere systemgendannelse. Højreklik på "Denne Computer" på skrivebordet, vælg egenskaber og fanebladet "Systemgendannelse" og sæt flueben i "Deaktiver systemgendannelse". Klik ok og genstart. Afinstaller Messenger Plus! 2 & eMule i Tilføj/fjern programmer. Kør en ny scanning med HJT og sæt flueben ved disse: F0 - system.ini: Shell= F2 - REG:system.ini: Shell= O2 - BHO: (no name) - {00000015-A527-34E7-25C2-03A4E313B2E9} - c:WINDOWSsystem32winsrvs_1.dll O2 - BHO: (no name) - {001F2570-5DF5-11d3-B991-00A0C9BB0874} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O3 - Toolbar: eBay Toolbar - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O4 - HKLM..Run: [TkBellExe] "C:ProgrammerFælles filerRealUpdate_OB ealsched.exe" -osboot O4 - HKLM..Run: [MessengerPlus2] "C:ProgrammerMessenger Plus! 2MsgPlus.exe" O4 - HKLM..Run: [QuickTime Task] "C:ProgrammerQuickTimeqttask.exe" -atboottime O4 - HKLM..Run: [SunJavaUpdateSched] C:ProgrammerJavaj2re1.4.2_05 injusched.exe O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe O4 - HKLM..Run: [Winad Client] C:Program FilesWinad ClientWinad.exe O4 - HKLM..Run: [WebRebates0] "C:ProgrammerWeb_RebatesWebRebates0.exe" O4 - HKCU..Run: [LDM] C:ProgrammerLogitechDesktop Messenger8876480ProgramBackWeb-8876480.exe O4 - HKCU..Run: [MessengerPlus2] "C:ProgrammerMessenger Plus! 2MsgPlus.exe" /WinStart O4 - HKLM..RunOnce: [djtopr1150.exe] "C:DOCUME~1ANDERS~1LOKALE~1Tempdjtopr1150.exe" O4 - Global Startup: eBay Toolbar.LNK = C:ProgrammereBayeBay Toolbar4.4.0.1ebaytbar.exe O4 - Global Startup: MsSvc32.exe O4 - Global User Startup: eBay Toolbar.LNK = C:ProgrammereBayeBay Toolbar4.4.0.1ebaytbar.exe O4 - Global User Startup: MsSvc32.exe O8 - Extra context menu item: Web Rebates - file://C:ProgrammerWeb_RebatesSy1150Tp1150scri1150a.htm O9 - Extra button: eBay Toolbar (HKLM) O9 - Extra 'Tools' menuitem: eBay Toolbar (HKLM) O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} - O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com[...] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com[...] Luk alle øvrige programvinduer så kun HJT er åben. Klik på ”Fix checked”. Luk programmet og genstart i fejlsikret tilstand (tryk F8 efter POST skærmen). Find og slet disse filer & mapper (husk at ændre mappeindstillinger så du kan se skjulte filer samt systemfiler): c:\WINDOWS\system32\winsrvs_1.dll C:\Programmer\eBay\ c:\WINDOWS\system32\MsSvc32.exe C:\Programmer\Messenger Plus! 2\ C:\Program Files\Winad Client\ C:\Programmer\Web_Rebates\ C:\DOCUME~1\ANDERS~1\LOKALE~1\Temp\djtopr1150.exe Genstart normalt. Kør en ny scanning med HJT og smid loggen herind til kontrol. Sørg for at bruge den nyeste version af HJT - http://www.mdegn.dk[...]
--
/Armageddon - [email protected] http://www.mdegn.dk[...]
#2
rUb!n4z
Semi Supporter
21-10-2004 16:51

Rapporter til Admin
Hej Armageddon! Tak for dit svar, men hvorfor skal jeg uninstalle emule og msn plus? -Anders
--
"Life is so... Whatever!" Kelly Marquette aKa Skeletor
#3
Armageddon
Moderator
21-10-2004 16:56

Rapporter til Admin
Fordi de er snavs og ikke bringer noget godt med sig. Det er muligt at du er glad for programmerne, men du må vælge mellem disse programmer inkl. en masse snavs eller en ren computer.
--
/Armageddon - [email protected] http://www.mdegn.dk[...]
#4
rUb!n4z
Semi Supporter
21-10-2004 18:15

Rapporter til Admin
Hej igen! Her er min nye log. Skal lige siges jeg ikke har fjernet eBay toolbar... Logfile of HijackThis v1.98.2 Scan saved at 18:14:51, on 21-10-2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSSystem32Ati2evxx.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSExplorer.EXE C:WINDOWSsystem32spoolsv.exe C:WINDOWSSystem32DRIVERSCDANTSRV.EXE C:WINDOWSSystem32svchost.exe C:WINDOWSSystem32wuauclt.exe C:ProgrammerLogitechiTouchiTouch.exe C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE C:ProgrammerD-Toolsdaemon.exe C:ProgrammeriTunesiTunesHelper.exe C:WINDOWSSOUNDMAN.EXE C:ProgrammerGoogleGmail Notifiergnotify.exe C:WINDOWSSystem32ctfmon.exe C:ProgrammerMicrosoft ActiveSyncWCESCOMM.EXE C:ProgrammeriPodiniPodService.exe C:ProgrammerSpybot - Search & DestroyTeaTimer.exe C:progra~1steamsteam.exe C:ProgrammereBayeBay Toolbar4.4.0.1ebaytbar.exe C:ProgrammerRed Chair SoftwareAnapod Exploreranamgr.exe C:ProgrammerMSN Messengermsnmsgr.exe C:ProgrammerInternet ExplorerIEXPLORE.EXE C:WINDOWSExplorer.EXE J:Ny mappeNy mappeNy mappeNy mappeNy mappeNy mappeNy mappeNy mappeHijackThis.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.dk[...] R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = localhost R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks O2 - BHO: (no name) - {00000015-A527-34E7-25C2-03A4E313B2E9} - (no file) O2 - BHO: eBay Helper Object - {001F2570-5DF5-11d3-B991-00A0C9BB0874} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:programmergooglegoogletoolbar1.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:programmergooglegoogletoolbar1.dll O3 - Toolbar: eBay Toolbar - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O4 - HKLM..Run: [zBrowser Launcher] C:ProgrammerLogitechiTouchiTouch.exe O4 - HKLM..Run: [EM_EXEC] C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit O4 - HKLM..Run: [DAEMON Tools-1033] "C:ProgrammerD-Toolsdaemon.exe" -lang 1033 O4 - HKLM..Run: [iTunesHelper] C:ProgrammeriTunesiTunesHelper.exe O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM..Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:ProgrammerGoogleGmail Notifiergnotify.exe O4 - HKLM..Run: [Winad Client] C:Program FilesWinad ClientWinad.exe O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe O4 - HKCU..Run: [H/PC Connection Agent] "C:ProgrammerMicrosoft ActiveSyncWCESCOMM.EXE" O4 - HKCU..Run: [SpybotSD TeaTimer] C:ProgrammerSpybot - Search & DestroyTeaTimer.exe O4 - HKCU..Run: [Steam] "c:progra~1steamsteam.exe" -silent O4 - HKCU..Run: [msnmsgr] "C:ProgrammerMSN Messengermsnmsgr.exe" /background O4 - Startup: Anapod Manager.lnk = C:ProgrammerRed Chair SoftwareAnapod Exploreranamgr.exe O4 - Global Startup: eBay Toolbar.LNK = C:ProgrammereBayeBay Toolbar4.4.0.1ebaytbar.exe O4 - Global User Startup: eBay Toolbar.LNK = C:ProgrammereBayeBay Toolbar4.4.0.1ebaytbar.exe O8 - Extra context menu item: &Google Search - res://c:programmergoogleGoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Download with GetRight - C:ProgrammerGetRightGRdownload.htm O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:PROGRA~1MICROS~3OFFICE11EXCEL.EXE/3000 O8 - Extra context menu item: Open with GetRight Browser - C:ProgrammerGetRightGRbrowse.htm O8 - Extra context menu item: Translate into English - res://c:programmergoogleGoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:WINDOWSSystem32msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:WINDOWSSystem32msjava.dll O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:ProgrammerMicrosoft ActiveSyncinetrepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:ProgrammerMicrosoft ActiveSyncinetrepl.dll O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:ProgrammerMicrosoft ActiveSyncinetrepl.dll O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3OFFICE11REFIEBAR.DLL O9 - Extra button: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O9 - Extra 'Tools' menuitem: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} - O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - O17 - HKLMSystemCCSServicesTcpip..{8797E844-69B0-480B-9A91-EC892C437062}: NameServer = 192.168.2.1 O17 - HKLMSystemCCSServicesTcpip..{F54E0DEE-9163-42B0-B68D-8088A0D1C35A}: NameServer = 192.168.2.1 O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:ProgrammerFælles filerMicrosoft SharedHelphxds.dll -Anders
--
"Life is so... Whatever!" Kelly Marquette aKa Skeletor
#5
rUb!n4z
Semi Supporter
21-10-2004 20:32

Rapporter til Admin
Armageeeeeeeeeeeeeeeeeeeeeddon? :)
--
"Life is so... Whatever!" Kelly Marquette aKa Skeletor
#6
Armageddon
Moderator
21-10-2004 20:58

Rapporter til Admin
Fix lige disse igen: O2 - BHO: (no name) - {00000015-A527-34E7-25C2-03A4E313B2E9} - (no file) O4 - HKLM..Run: [Winad Client] C:Program FilesWinad ClientWinad.exe O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} - O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - Luk alle øvrige programvinduer så kun HJT er åben. Klik på ”Fix checked”. Luk programmet og genstart maskinen. Smid en ny log ind til en sidste kontrol. Grunden til at eBay skulle fjernes var at programmet indeholder spyware, og rapporterer hjem om dine internetvaner. Nu er du klar over det, og kan selv tage stilling til om du synes det er OK.
--
/Armageddon - [email protected] http://www.mdegn.dk[...]
#7
rUb!n4z
Semi Supporter
21-10-2004 21:04

Rapporter til Admin
Logfile of HijackThis v1.98.2 Scan saved at 21:04:30, on 21-10-2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:WINDOWSSystem32smss.exe C:WINDOWSsystem32winlogon.exe C:WINDOWSsystem32services.exe C:WINDOWSsystem32lsass.exe C:WINDOWSSystem32Ati2evxx.exe C:WINDOWSsystem32svchost.exe C:WINDOWSSystem32svchost.exe C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSExplorer.EXE C:WINDOWSsystem32spoolsv.exe C:WINDOWSSystem32DRIVERSCDANTSRV.EXE C:WINDOWSSystem32svchost.exe C:WINDOWSSystem32wuauclt.exe C:ProgrammerLogitechiTouchiTouch.exe C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE C:ProgrammeriTunesiTunesHelper.exe C:WINDOWSSystem32ctfmon.exe C:ProgrammerMicrosoft ActiveSyncWCESCOMM.EXE C:ProgrammeriPodiniPodService.exe J:Ny mappeNy mappeNy mappeNy mappeNy mappeNy mappeNy mappeNy mappeHijackThis.exe R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.dk[...] R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = localhost R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks O2 - BHO: eBay Helper Object - {001F2570-5DF5-11d3-B991-00A0C9BB0874} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:programmergooglegoogletoolbar1.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:programmergooglegoogletoolbar1.dll O3 - Toolbar: eBay Toolbar - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O4 - HKLM..Run: [zBrowser Launcher] C:ProgrammerLogitechiTouchiTouch.exe O4 - HKLM..Run: [EM_EXEC] C:PROGRA~1LogitechMOUSEW~1SYSTEMEM_EXEC.EXE O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup O4 - HKLM..Run: [nwiz] nwiz.exe /install O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit O4 - HKLM..Run: [DAEMON Tools-1033] "C:ProgrammerD-Toolsdaemon.exe" -lang 1033 O4 - HKLM..Run: [iTunesHelper] C:ProgrammeriTunesiTunesHelper.exe O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM..Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:ProgrammerGoogleGmail Notifiergnotify.exe O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe O4 - HKCU..Run: [H/PC Connection Agent] "C:ProgrammerMicrosoft ActiveSyncWCESCOMM.EXE" O4 - HKCU..Run: [SpybotSD TeaTimer] C:ProgrammerSpybot - Search & DestroyTeaTimer.exe O4 - HKCU..Run: [Steam] "c:progra~1steamsteam.exe" -silent O4 - HKCU..Run: [msnmsgr] "C:ProgrammerMSN Messengermsnmsgr.exe" /background O4 - Startup: Anapod Manager.lnk = C:ProgrammerRed Chair SoftwareAnapod Exploreranamgr.exe O4 - Global Startup: eBay Toolbar.LNK = C:ProgrammereBayeBay Toolbar4.4.0.1ebaytbar.exe O4 - Global User Startup: eBay Toolbar.LNK = C:ProgrammereBayeBay Toolbar4.4.0.1ebaytbar.exe O8 - Extra context menu item: &Google Search - res://c:programmergoogleGoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Download with GetRight - C:ProgrammerGetRightGRdownload.htm O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:PROGRA~1MICROS~3OFFICE11EXCEL.EXE/3000 O8 - Extra context menu item: Open with GetRight Browser - C:ProgrammerGetRightGRbrowse.htm O8 - Extra context menu item: Translate into English - res://c:programmergoogleGoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:WINDOWSSystem32msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:WINDOWSSystem32msjava.dll O9 - Extra button: Opret Foretrukken på mobil enhed - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:ProgrammerMicrosoft ActiveSyncinetrepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:ProgrammerMicrosoft ActiveSyncinetrepl.dll O9 - Extra 'Tools' menuitem: Opret Foretrukken på mobil enhed... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:ProgrammerMicrosoft ActiveSyncinetrepl.dll O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3OFFICE11REFIEBAR.DLL O9 - Extra button: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O9 - Extra 'Tools' menuitem: eBay Toolbar - {92D7F210-7F20-11d3-8157-0090278B20DE} - C:ProgrammereBayeBay Toolbar4.4.0.1eBayBand.dll O17 - HKLMSystemCCSServicesTcpip..{8797E844-69B0-480B-9A91-EC892C437062}: NameServer = 192.168.2.1 O17 - HKLMSystemCCSServicesTcpip..{F54E0DEE-9163-42B0-B68D-8088A0D1C35A}: NameServer = 192.168.2.1 O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:ProgrammerFælles filerMicrosoft SharedHelphxds.dll -Anders -Tak for hjælpen :)
--
"Life is so... Whatever!" Kelly Marquette aKa Skeletor
#8
Armageddon
Moderator
21-10-2004 21:20

Rapporter til Admin
Så ser det fornuftigt ud. Aktiver bare systemgendannelse igen.
--
/Armageddon - [email protected] http://www.mdegn.dk[...]

Opret svar til indlægget: HJT log igen igen igen igen igen

Grundet øget spam aktivitet fra gæstebrugere, er det desværre ikke længere muligt, at oprette svar som gæst.

Hvis du ønsker at deltage i debatten, skal du oprette en brugerprofil.

Opret bruger | Login
NYHEDSBREV
Afstemning


ANNONCE